Buyer fit
Good fit when
- ✓Nordic buyers already committed to Microsoft Azure and Sentinel
- ✓Organizations that want MDR data to stay in their own Azure environment
- ✓Teams that want a step-up path from business-hours monitoring to 24/7 MDR
Watch out when
- ×Buyers that need public MDR pricing or response SLAs before sales engagement
- ×Teams that want endpoint and network detection included in a base MDR package
- ×Organizations that need autonomous containment without internal approval
Coverage
0 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Tiered custom quote.
How pricing works+−
Innofactor publishes Basic, Standard and Advanced MDRaaS tiers, each marked ask for pricing.
Not published
Cost caveats
- –Tier1 and Tier2 cover regular business hours, not 24/7.
- –Endpoint and network detection are add-ons, so base SIEM-only scope may be narrower than buyers expect.
- –Microsoft Sentinel cost depends on data ingestion, retention, analytics tiers and related Azure services.
2 more+−
- –Public pages do not publish named response actions or response SLAs.
- –Customers keep ownership of logs and incidents, so internal responsibility for mitigation should be clear before signing.
What costs extra (5)+−
- –Exact MDRaaS pricing requires an Innofactor quote
- –EDR with the Microsoft Defender product family is an add-on service
- –NDR with Darktrace is an add-on service
- –Tier3 Advanced is required for 24/7 service and threat hunting
- –Microsoft Azure, Microsoft Sentinel, Defender and Darktrace licensing can affect total cost
Team and access
Certifications
Reputation
Innofactor has limited MDR-specific public review volume. The public buyer case rests on Nordic Microsoft expertise, Sentinel in the customer's Azure environment, tiered service levels and clear customer control of logs and incidents. Buyers should validate response authority, total licensing cost, add-on scope and Tier3 operating model before signing.
What customers praise
- ✓Microsoft Sentinel runs in the customer's Azure environment
- ✓Nordic delivery across Finland, Sweden, Denmark and Norway
- ✓Tiering makes the difference between business-hours monitoring and 24/7 service explicit
Common complaints
- ×No public MDRaaS pricing
- ×Endpoint and network detection are add-ons
- ×Specific response actions and SLA terms need quote-level confirmation
No meaningful Reddit signal found for Innofactor MDRaaS specifically.
Questions to ask
- 1.
Which tier are we buying and does it include 24/7 monitoring?
- 2.
Are EDR, NDR, Defender, Darktrace and Sentinel licenses included or billed separately?
- 3.
Which response actions can Innofactor take directly and which require our approval?
- 4.
What contractual SLA applies to high-severity triage, escalation and response?
- 5.
What data, analytics rules, reports and incident records remain in our Azure environment if we leave?
- 6.
Which Microsoft Sentinel content is standard and which detections are customized for our environment?
- 7.
How often is threat hunting performed on Tier3 Advanced?
- 8.
Which CSOC location, shift model and analyst certifications apply to our contract?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
- –MDR analyst headcount or analyst-to-customer ratio is not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
